VYPR
Vypr IntelligenceAI-generatedSep 1, 2026· 16 CVEs

Mozilla Thunderbird: 16 Vulnerabilities Including Critical Sandbox Escapes Disclosed Together

Mozilla patched 16 Thunderbird vulnerabilities on September 1, 2026, including critical sandbox escapes and privilege escalation flaws, urging users to update.

Key findings

  • Mozilla disclosed 16 Thunderbird vulnerabilities on September 1, 2026, including two critical sandbox escapes.
  • Flaws impacted email parsing, remote content handling, calendar invitations, and internal components.
  • Privilege escalation and memory corruption were key themes across several high-severity CVEs.
  • Critical CVEs CVE-2026-84121 and CVE-2026-84119 are sandbox escapes due to use-after-free.
  • Patches are available in Thunderbird versions 155, 153.2, and 140.15.

On September 1, 2026, Mozilla Corporation disclosed a significant batch of 16 vulnerabilities affecting its Thunderbird email client. The vulnerabilities, disclosed within a nine-hour window, span a range of severity, including two critical sandbox escape flaws. These issues highlight potential risks in email handling, remote content loading, and internal component security.

Several vulnerabilities stem from improper handling of email content and headers. CVE-2026-84640, a one-byte buffer read overflow, could be triggered by a maliciously constructed mail header. Another issue, CVE-2026-84639, involved the use of uninitialized memory when encountering errors in certain MIME bodies. Additionally, CVE-2026-84642 could allow unintended hostnames to serve remote attachments due to improper escaping in the mail.allowed_attachment_hostnames configuration.

Remote content and calendar invitations also presented attack vectors. CVE-2026-84637 detailed how malicious calendar invitations with file URI attachments could bypass protections and launch local or network-hosted executables on Windows, potentially under misleading filenames if new invitation display features were enabled. Meanwhile, CVE-2026-84641 described a use-after-free and heap-memory disclosure vulnerability exploitable by a malicious IMAP server, with heap contents potentially being persisted.

A cluster of vulnerabilities related to memory corruption and privilege escalation were also patched. CVE-2026-84145, CVE-2026-84144, CVE-2026-84143, and CVE-2026-84142, all internally found bugs, showed evidence of memory corruption or other security-relevant defects, with the potential for exploitation. More critically, CVE-2026-84131 and CVE-2026-84123, both high-severity flaws, involved privilege escalation due to invalid pointers and use-after-free conditions in graphics components, respectively. CVE-2026-84128, another high-severity flaw, was found in the WebDriver BiDi component, also leading to privilege escalation.

The most severe issues were CVE-2026-84121 and CVE-2026-84119, both critical sandbox escapes stemming from use-after-free vulnerabilities in the DOM: Security and DOM: Navigation components, respectively. These flaws could allow attackers to break out of Thunderbird's security sandbox.

Mozilla addressed these vulnerabilities across several updates. Thunderbird 155, Thunderbird 153.2, and Thunderbird 140.15 were released to fix many of these issues. Specific versions like Thunderbird 153 and Thunderbird 153.2 were mentioned for particular CVEs, indicating a staggered rollout of fixes. Users are strongly advised to update to the latest available version of Thunderbird to protect against these newly disclosed threats.

This batch of vulnerabilities underscores the ongoing need for vigilance in email client security. The variety of attack vectors, from header manipulation to complex memory corruption issues, highlights the multifaceted nature of modern software vulnerabilities. Users should ensure their Thunderbird clients are updated promptly to mitigate risks associated with these disclosures.

CVE-2026-84642, CVE-2026-84641, CVE-2026-84640, CVE-2026-84639, CVE-2026-84637, CVE-2026-84145, CVE-2026-84144, CVE-2026-84143, CVE-2026-84142, CVE-2026-84141, CVE-2026-84140, CVE-2026-84131, CVE-2026-84128, CVE-2026-84123, CVE-2026-84121, CVE-2026-84119

AI-written article. Grounded in 16 CVE records listed below.